Kernel Information Leak Defenses & Dmesg Restrict Simulator
CONFIG_SECURITY_DMESG_RESTRICT=y & kptr_restrict=2
Query /proc/kallsyms
Read dmesg Buffer
Printk Pointer (%pK)
Mode: Hardened (kptr=2, dmesg=1)
Next Step ⏭
Auto Play ▶
Reset ↺
Theme 🌓
Unprivileged User (UID 1000)
Read /proc/kallsyms
cat /proc/kallsyms
Seeking KASLR base offset
Read dmesg Log Buffer
klogctl(SYSLOG_ACTION_READ)
open("/dev/kmsg")
Seeking crash/driver logs
Read Sysfs / Procfs Node
cat /proc/vuln_info_leaks
Inspects %pK & %p formats
Seeking kernel heap/stack
Kernel Information Gatekeeper
dmesg_restrict=1 & kptr_restrict=2
Access Control & Sanitizer
1. kallsyms: kptr_restrict >= 1
2. dmesg: capable(CAP_SYSLOG)
3. SipHash pointer hashing (%p)
Policy Decision Matrix
kptr_restrict=2: Redact all to zeros
dmesg_restrict=1: Reject unprivileged
%p: SipHash obscures memory layout
Status: Complete address obfuscation
Information Output
REDACTED / GATED
Symbols: 0000000000000000
dmesg: -EPERM (Blocked)
KASLR secrecy preserved
POINTER EXPOSED
Raw: 0xffff800081234567
dmesg: Unrestricted read
KASLR offset compromised!
Exploit ROP chain unlocked
Ready. Choose a scenario: Query /proc/kallsyms, Read dmesg Buffer, or Printk Pointer.
Step: 0/4